Vulnerabilities > Nextcloud > High

DATE CVE VULNERABILITY TITLE RISK
2020-08-10 CVE-2020-8224 Code Injection vulnerability in Nextcloud Desktop
A code injection in Nextcloud Desktop Client 2.6.4 allowed to load arbitrary code when placing a malicious OpenSSL config into a fixed directory.
local
low complexity
nextcloud CWE-94
7.8
2020-05-12 CVE-2020-8156 Improper Certificate Validation vulnerability in multiple products
A missing verification of the TLS host in Nextcloud Mail 1.1.3 allowed a man in the middle attack.
network
high complexity
nextcloud fedoraproject CWE-295
7.0
2020-05-12 CVE-2020-8154 Authorization Bypass Through User-Controlled Key vulnerability in Nextcloud Server
An Insecure direct object reference vulnerability in Nextcloud Server 18.0.2 allowed an attacker to remote wipe devices of other users when sending a malicious request directly to the endpoint.
network
low complexity
nextcloud CWE-639
7.7
2020-05-12 CVE-2020-8153 Incorrect Permission Assignment for Critical Resource vulnerability in multiple products
Improper access control in Groupfolders app 4.0.3 allowed to delete hidden directories when when renaming an accessible item to the same name.
network
low complexity
nextcloud fedoraproject CWE-732
8.1
2020-02-04 CVE-2019-15613 Insufficient Verification of Data Authenticity vulnerability in multiple products
A bug in Nextcloud Server 17.0.1 causes the workflow rules to depend their behaviour on the file extension when checking file mimetypes.
network
low complexity
nextcloud opensuse CWE-345
8.0
2018-08-12 CVE-2018-3775 Improper Authentication vulnerability in Nextcloud Server
Improper Authentication in Nextcloud Server prior to version 12.0.3 would allow an attacker that obtained user credentials to bypass the 2 Factor Authentication.
network
low complexity
nextcloud CWE-287
8.8
2018-07-05 CVE-2018-3761 Improper Authentication vulnerability in Nextcloud Server
Nextcloud Server before 12.0.8 and 13.0.3 suffer from improper authentication on the OAuth2 token endpoint.
network
low complexity
nextcloud CWE-287
8.1